Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
LibTIFF pal2rgb 4.0.9 - Heap Buffer Overflow
CVE-2017-1709511 dic 2017
tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-b
28RIESGO
abrir
Exploit-DB
Entrepreneur Bus Booking Script 3.0.4 - 'sourcebus' SQL Injection
CVE-2017-1760411 dic 2017
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
23RIESGO
abrir
Exploit-DB
PHP Multivendor Ecommerce 1.0 - 'sid' / 'searchcat' / 'chid1' SQL Injection
CVE-2017-1762411 dic 2017
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat o
23RIESGO
abrir
Exploit-DB
Readymade PHP Classified Script 3.3 - 'subctid' / 'mctid' SQL Injection
CVE-2017-1762611 dic 2017
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
Exploit-DB
Lawyer Search Script 1.1 - 'lawyer-list?city' SQL Injection
CVE-2017-1762011 dic 2017
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
23RIESGO
abrir
Exploit-DB
Opensource Classified Ads Script 3.2 - SQL Injection
CVE-2017-1762311 dic 2017
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir
Exploit-DB
Advanced Real Estate Script 4.0.7 - SQL Injection
CVE-2017-1760311 dic 2017
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_
23RIESGO
abrir
Exploit-DB
Food Order Script 1.0 - 'list?city' SQL Injection
CVE-2017-1761411 dic 2017
Food Order Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DB
Foodspotting Clone Script 1.0 - 'quicksearch.php?q' SQL Injection
CVE-2017-1761711 dic 2017
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
23RIESGO
abrir
Exploit-DB
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
CVE-2017-1761811 dic 2017
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
CVE-2017-100040511 dic 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
Exploit-DB
Apple macOS - 'getrusage' Stack Leak Through struct Padding
CVE-2017-1386911 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
Vanguard 1.4 - SQL Injection
CVE-2017-1787311 dic 2017
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RIESGO
abrir
Exploit-DB
Apple macOS - 'necp_get_socket_attributes' so_pcb Type Confusion
CVE-2017-1385511 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-1761911 dic 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DB
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-1762211 dic 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir
Exploit-DB
Hot Scripts Clone 3.1 - 'subctid' / 'mctid' SQL Injection
CVE-2017-1761211 dic 2017
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
Exploit-DB
Facebook Clone Script 1.0 - 'id' / 'send' SQL Injection
CVE-2017-1761511 dic 2017
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
Exploit-DB
Professional Service Script 1.0 - 'service-list?city' SQL Injection
CVE-2017-1762511 dic 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RIESGO
abrir
Exploit-DB
Apple macOS XNU Kernel - Memory Disclosure due to bug in Kernel API for Detecting Kernel Memory Disclosures
CVE-2017-1386511 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
Vanguard 1.4 - Arbitrary File Upload
CVE-2017-1787411 dic 2017
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product
23RIESGO
abrir
Exploit-DB
MLM Forex Market Plan Script 2.0.4 - 'newid' / 'eventid' SQL Injection
CVE-2017-1763511 dic 2017
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eve
23RIESGO
abrir
Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-1764111 dic 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
Exploit-DB
Multireligion Responsive Matrimonial 4.7.2 - 'succid' SQL Injection
CVE-2017-1763111 dic 2017
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
23RIESGO
abrir
Exploit-DB
Basic Job Site Script 2.0.5 - SQL Injection
CVE-2017-1764211 dic 2017
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RIESGO
abrir
Exploit-DB
Car Rental Script 2.0.4 - 'val' SQL Injection
CVE-2017-1763711 dic 2017
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RIESGO
abrir
Exploit-DB
Secure E-commerce Script 2.0.1 - 'searchcat' / 'searchmain' SQL Injection
CVE-2017-1762911 dic 2017
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_d
23RIESGO
abrir
Exploit-DB
Readymade Video Sharing Script 3.2 - SQL Injection
CVE-2017-1762711 dic 2017
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RIESGO
abrir
Exploit-DB
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
CVE-2017-1763611 dic 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir
Exploit-DB
Single Theater Booking Script 3.2.1 - 'findcity.php?q' SQL Injection
CVE-2017-1763411 dic 2017
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
23RIESGO
abrir
anteriorpágina 113 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.